Checklist · School Admissions Head

DPDPA Checklist for School Admissions Heads

Admissions is where a school collects the most personal data and controls it the least — paper forms, WhatsApp enquiries, agent referrals, Aadhaar photocopies, sibling records. Under the DPDP Act, 2023 the school is the Data Fiduciary and the admissions head owns the collection point. This checklist covers what to fix before the next cycle.

Last reviewed: 14 August 2026

What must a school admissions head do for DPDPA compliance?

  1. Audit the admission form field by field, and delete what you can't justify. Take last year's form and write the purpose next to every field. Father's occupation, mother's income, caste category where not required for a mandated quota, previous school fee history, blood group for a day scholar — if you can't name the purpose in one sentence, drop it. Section 6(1) limits consent to data necessary for the specified purpose, so an unjustifiable field is a defect even if the parent happily filled it in. Owner: you. Artefact: annotated form with a purpose next to each field.
  2. Stop taking Aadhaar photocopies as the default identity proof. Aadhaar is not generally mandatory for school admission under typical board rules, and the Aadhaar Act permits offline verification routes. Where you need age or identity proof, accept birth certificate or passport as equal alternatives and say so on the form. If you do accept Aadhaar, use masked Aadhaar or offline XML, never store a full photocopy in an open file, and never store the number alongside the photograph in the same accessible record. Confirm your board's current circular before treating any ID as compulsory.
  3. Split the consent, don't bundle it. One tick-box covering "admission processing, photography, marketing, alumni communication and third-party programmes" fails. Separate consents: (a) admission processing, (b) photographs and video for school publicity, (c) sharing with third-party vendors such as uniform or transport partners, (d) marketing to parents. Each must be refusable without losing the admission — consent must be unconditional under Section 6. Rule 3 requires an itemised description of the personal data and each specified purpose in plain language. This is the single most common defect in Indian school forms.
  4. Verify the parent once, at the point of admission. Section 9(1) requires verifiable parental consent, and Rule 10 requires reasonable due diligence that the consenting adult is an identifiable adult who has completed 18 years, by one of three routes: reliable identity and age details the school already holds; details voluntarily provided; or a virtual token issued by an authorised entity, including a Digital Locker service provider. Verify identity at admission, then bind every later consent (trips, medical, media) to that verified parent record. A tick-box saying "I am the parent" verifies nothing. Handle Rule 11 separately for students with disability who have a lawful guardian — do not run them through the ordinary parent flow.
  5. Fix the rejected-applicant pile. Most schools keep every rejected application indefinitely. Once the admission decision is communicated and any appeal window closes, the specified purpose is served and Section 8(7) requires erasure, subject to any statutory retention rule and the one-year floors in Rule 6(1)(e) and Rule 8(3). Set a written retention policy — a typical operational default is to delete rejected applications within 90 days of the cycle closing, retaining only an anonymised count for reporting. That 90-day line is a suggested policy, not a statutory period. Include the physical files, not just the spreadsheet.
  6. Kill the shared WhatsApp enquiry number and the parent groups you don't control. Enquiries arriving on a staff member's personal phone means personal data sitting on a device you have no rights over when that person resigns. Move admissions enquiries to a school-owned number or form. For parent groups, use broadcast lists or a school app rather than groups where every parent's number is visible to every other parent — that visibility is a disclosure you never obtained consent for.
  7. Put your consultants, agents and photographers under contract. Admission consultants, education fairs, event photographers and the vendor running your online form are all Data Processors. Section 8(2) requires a valid contract before they process on your behalf, Rule 6(1)(f) requires security provisions in it, and you remain liable for their failure. Minimum terms: process only on your instructions, no onward sharing, no reuse of child data for the vendor's own profiling or ads, delete or return on termination, notify you of any incident within hours.
  8. Serve the notice at the point of collection, in the parent's language. Section 5 requires a standalone plain-language notice before or with consent — not a clause in the prospectus. Rule 3 requires it to be presented independently of other terms, in English or any Eighth Schedule language, with an itemised description of the personal data, the specified purposes, and a means to withdraw as easily as consent was given. For a Hindi-belt school, a Hindi notice is not a nicety. Where consent was obtained before commencement, Section 5(2) requires a notice to the current roll as soon as reasonably practicable — own the send list with the Principal.
  9. Name a contact person and publish the route for parent requests. Rule 9 requires you to publish the business contact information of a person who can answer questions about processing — on the website and on the admission form. Rule 14(1) requires you to publish how a parent makes an access, correction or erasure request and any identifier you need. Rule 14(3) requires the grievance system to respond within a period not exceeding ninety days — that 90-day figure is the grievance ceiling, not the SLA for every rights request. Rights requests that hit admissions first (correction of date of birth, name, parent phone; erasure of a rejected application) still need a published Rule 14(1) route. A DPO is not required unless you are notified as a Significant Data Fiduciary.
  10. Write down where admission data goes after the form — and build the 18th-birthday trigger. Map it: which staff can open the folder, which of MIS, fee software, transport, bus GPS and the school app receives it, and whether any vendor hosts outside India. You need this map to answer a Section 11 access request and to act within the breach clock if a vendor is compromised. Separately, a child is anyone under 18, so Section 9 covers Class 12 — the day a student turns 18, consent transfers to them. Your admission/ERP record needs a date-of-birth trigger that flags these students for re-consent in their own name.

Frequently asked questions

Parents give us this data willingly. Do we still need all this?

Yes. Willing handover is not consent under the Act, and for under-eighteens Section 9(1) requires verifiable parental consent regardless of how cooperative the parent is. The Section 7(a) route — data voluntarily provided for a purpose the person hasn't objected to — does not rescue you here, because the data subject is the child and the child cannot consent. Practically, the risk isn't the happy parent; it's the one parent in three thousand who is in a custody dispute, or whose child was denied admission, and who now asks what you did with the file.

Can we use admission photographs on our website, brochures and Instagram?

Only with a consent for that specific purpose, collected separately from admission consent, and refusable without consequence. Section 6 requires consent to be specific, informed and unconditional — so admission cannot be made conditional on agreeing to marketing photographs. Section 9(3) separately bars targeted advertising directed at children, so a photograph used in a paid ad campaign aimed at prospective students is a different and riskier act than the same photo in a printed prospectus. Keep a withdrawal route that actually works, because Section 6(4) lets a parent withdraw at any time and you then need to pull that image from live channels. Never publish a child's photograph alongside their full name, class and bus route in the same asset.

We're a school — aren't we exempt from most of this?

Partially, and the exemption is narrower than most admissions heads assume. Rule 12 read with Fourth Schedule Part A(3) and A(5), and Part B(4), covers tracking and behavioural monitoring for educational activities and enrolled-child safety — which is what makes bus GPS and campus safety systems workable. It does not exempt you from notice, verifiable parental consent for admission, medical or photography processing, security safeguards, retention limits, breach reporting or grievance redressal. And nothing exempts Section 9(2): processing likely to have a detrimental effect on a child's well-being is never permitted. Substantive obligations bite 13 May 2027, which for admissions means the 2027 cycle is the last one you can run unfixed.

Official sources

Free DPDPA gap scan for schools — and a badge for your website

Answer 20 questions about your admission form, your ed-tech vendors, your CCTV and transport tracking, and how you store student records. You get a written gap report scored against Section 9, Rule 10 and the security safeguards duty — no cost, no call required. Schools that clear the baseline get a DPDPA Ready badge to display for parents and at admissions.

Run the free gap scan Talk to us

Takes 10 minutes. Report emailed to your Principal or Correspondent. Nothing published without your permission.

Disclaimer: Privigo is not a law firm. This page provides operational compliance guidance only. For institution-specific obligations, work with qualified Indian legal counsel.